
Educational sandbox and dynamic proof-of-concept scanner for CVE-2025-11844 XPath injection in Hugging Face smolagents library, enabling local data extraction and DOM traversal auditing.
An educational auditing sandbox and dynamic proof-of-concept scanner demonstrating the XPath Injection vulnerability found within Hugging Face's smolagents library (up to version 1.2.0).
| Metric | Details |
|---|---|
| CVE ID | CVE-2025-11844 |
| Target Component | search_item_ctrl_f function inside vision_web_browser.py |
| Vulnerability Type | Improper Input Validation -> XPath Injection / DOM Breakout |
| Impact Scope | Local Data Extraction, Information Disclosure, Arbitrary DOM Traversal |
The target framework uses an un-sanitized string directly inside an internal XPath querying function:
//*[contains(text(), 'USER_INPUT_HERE')]